Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-95619

Опубликовано: 22 сент. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

Отчет

This Moderate impact flaw affects applications compiled with older gcc versions on Red Hat Enterprise Linux 8 and 9. An integer overflow in the libstdc++ aligned operator new could lead to undersized memory allocations, potentially causing memory corruption or application instability when processing specific large allocation requests.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gccNot affected
Red Hat Enterprise Linux 10mingw-gccNot affected
Red Hat Enterprise Linux 6compat-gcc-295Not affected
Red Hat Enterprise Linux 6compat-gcc-296Not affected
Red Hat Enterprise Linux 6compat-gcc-32Not affected
Red Hat Enterprise Linux 6compat-gcc-34Not affected
Red Hat Enterprise Linux 6gccNot affected
Red Hat Enterprise Linux 7compat-gcc-32Not affected
Red Hat Enterprise Linux 7compat-gcc-34Not affected
Red Hat Enterprise Linux 7compat-gcc-44Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2537811gcc: libstdc++ integer overflow in `new` operator

EPSS

Процентиль: 42%
0.00495
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
3 дня назад

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

CVSS3: 7.7
nvd
3 дня назад

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

CVSS3: 7.7
debian
3 дня назад

A flaw was found in libstdc++. An integer overflow can occur when proc ...

CVSS3: 7.7
github
3 дня назад

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

EPSS

Процентиль: 42%
0.00495
Низкий

7.7 High

CVSS3